Forum Discussion

Peter van Rossum's avatar
Peter van Rossum
Copper Contributor
Feb 09, 2018
Solved

External user permission error

Hi, in my environment I am not able to use gmail-addresses or hotmail-addresses for custom permissions. Is this a setting in Azure? Where do I change it so people are able to use these addresses?

Thanks.

  • This seems to be the same question that I answered on the Docs site? (https://docs.microsoft.com/en-us/information-protection/rms-client/client-classify-protect#comments) You can't currently use these type of addresses with custom permissions because these email addresses are not supported by Azure Information Protection. There isn't a setting that you enable for this in Azure - there are backend changes needed to be completed on the engineering side before this will work.

     

    As the other replies indicate, these types of addresses are supported when you use the new capabilities from Office 365 Message Encryption - so you can use them with email because Exchange Online is doing the authentication.  If you use these types of addresses with labels or protection templates, they will work with email (going through Exchange Online) but won't work if you protect a document outside email. For permissions to work with documents, the email address must be from a verified domain in Azure. You'll find more detailed information here: https://docs.microsoft.com/en-us/information-protection/plan-design/prepare#azure-information-protection-requirements-for-user-accounts

     

    It's understandably a very popular request to be able to use personal email addresses for documents as well as for emails.  As soon as the extra work is done, I'm sure it will be widely announced - and I'll update the docs to match!

Resources